Example output · Pages 2 and 3
The rest of the sample.
Client: [REDACTED] · Firm size: 40 people · Evidence date:
Example only
Red Amber Green Not Verified
| Status | Action | Owner | Timing |
| Red | Run and record a restore test for Microsoft 365 and practice data. | IT provider + Operations Director | Days 0–15 |
| Red | Remove two dormant privileged accounts and document emergency access. | IT provider | Days 0–15 |
| Not Verified | Reconcile the 42-person roster against endpoint management and encryption records. | Office Manager + IT provider | Days 0–30 |
| Amber | Approve a severity and escalation matrix with named business decision-makers. | Managing Partner + IT provider | Days 31–60 |
| Amber | Assign one business owner and one technical owner to every material system. | Operations Director | Days 31–60 |
| Green | Keep the monthly endpoint encryption exception report and quarterly review. | IT provider | Ongoing |
Example output · Page 03
90-day plan
Sequenced for ownership, evidence, and effort
-
Days 0–30
Close urgent gaps and material unknowns
- Disable dormant privileged accounts and confirm the current administrator roster.
- Reconcile staff, device management, encryption, and endpoint protection records.
- Complete one documented restore test using representative Microsoft 365 and practice data.
Done when: Signed administrator roster, reconciled device list, and restore record.
-
Days 31–60
Make ownership and escalation explicit
- Approve the system ownership map with business and technical owners.
- Agree on incident severity, decision authority, and escalation contacts.
- Add evidence checks to the employee offboarding checklist.
Done when: Approved ownership map, escalation matrix, and offboarding checklist.
-
Days 61–90
Make the evidence repeatable
- Schedule quarterly access and endpoint evidence reviews.
- Set the next recovery test date and assign the person who records it.
- Give leadership a one-page exception report for unresolved Red, Amber, and Not Verified items.
Done when: Review calendar, named owners, and first leadership exception report.
This example is not a penetration test, formal audit, certification, legal, privacy, or
insurance opinion. It does not promise any outcome.
See the full Technology Operations Review →